Description:

Openstack Nova has been updated to fix the following
security issues:

* CVE-2013-0280: Jonathan Murray from NCC Group, Joshua
Harlow from Yahoo! and Stuart Stent independently reported
a vulnerability in the parsing of XML requests in Keystone,
Nova and Cinder. By using entities in XML requests, an
unauthenticated attacker may consume excessive resources on
the Keystone, Nova or Cinder API servers, resulting in a
denial of service and potentially a crash. Authenticated
attackers may also leverage XML entities to read the
content of a local file on the Keystone API server. This
only affects servers with XML support enabled.
* CVE-2013-0335: Loganathan Parthipan (HP) and Rohit
Karajgi (NTT Data) independently reported a vulnerability
in Nova. If a user requests a console and then deletes the
VM, it is possible that the console token could allow
connectivity to a different VM before the console token
expires if the VNC port gets reused in that time period.
This issue can be worked around by disabling VNC support.
* CVE-2013-1838: Vish Ishaya reported a vulnerability
in Nova where there is no quota for Fixed IPs. Previously
the instance quota acted as a proxy for a Fixed IP quota,
but if your configuration allows an instance to consume
more than one Fixed IP via an extension such as multinic
then this is no longer true. Running out of Fixed IPs would
result in not being able to spawn new instances.

Patch Instructions:

To install this SUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product: